- Home
- Resources
- Integrations
- Black Duck Security Scanner
Claude Black Duck Security Scanner connectorWhat Claude can do in your Black Duck Security Scanner account.
The Claude Black Duck Security Scanner connector exposes 2 tools. Both read your code to look for vulnerabilities, 0 write anything, and 0 remain undocumented. Below: what Claude can scan on your machine, where the code goes, and what you need before it works.
Verified Trustpilot reviews · AI, automation & growth agency
What changes when Claude can run Black Duck scans
Instead of switching to a separate security tool after every round of edits, a developer asks Claude to check the work in plain words. Claude runs a Black Duck Signal scan on the project, reads the findings by severity and explains them in the conversation, so the fix can start while the code is still fresh in mind.
Check only what you just changed. With run_changes_security_scan, Claude scans the edits in a git project, either the work not yet committed or everything since a reference branch such as main, and returns counts by severity.
Audit a folder that matters. run_security_scan targets specific files or directories, which Black Duck recommends for projects without git or for a focused review of a sensitive path.
Turn a report into next steps. Both tools hand back a SARIF report and analysis guidance, which Claude can walk through finding by finding, one severity level at a time, in the same conversation.
What it will not do: the tools scan and report; no source says they modify your files. Nothing scans by itself on each commit either, since Claude acts only while it answers. And the scanned code leaves your machine for Black Duck's analysis service. For other families on this site, see the Integrations hub.
Five words to get straight
The Claude terms this page relies on, each explained once.
- Connector
- A link set up once between Claude and an outside service or program, so Claude can use it while it answers you.
- Tool
- One named action a connector makes available. Claude decides when to call it, and the directory sheet lists every tool by its name.
- Authorization
- The service's own screen where you grant Claude the access it will use afterwards. It is granted per person and can be taken back.
- Approval
- The confirmation Claude waits for before doing something that changes an account, shown in the chat at the point it matters.
- MCP
- The shared standard connectors are built on: it lets an assistant like Claude work with an outside service such as Black Duck.
Set up the Claude Black Duck Security Scanner connector
- 01
Find Black Duck in the list
Open Claude's settings, go to Customize, then Connectors, and locate Black Duck Security Scanner. On a Team or Enterprise workspace, an Owner or Primary Owner enables it for the organization before members can use it individually.
- 02
Start the connection
Click Connect on its row and finish what the window asks. If the link fails later, choose Disconnect and connect again, which is how Claude expects a broken connection to be repaired.
- 03
Read what you approve
Where an authorization screen appears, read it before accepting: it is written by the service, not by Claude, and it sets the scope of access Claude will use from then on.
The 2 scanning tools
Black Duck Security Scanner gives Claude 2 tools: 2 that read your account, 0 that change something in it.
Both tools are described in Black Duck's own documentation. Names stay as Claude displays them, in English.
- 2 read
What Claude reads (2)
2 toolsTwo tools that analyze your code and report findings without editing it.
run_changes_security_scan
Runs a fast, incremental scan limited to the code you touched in a git project: staged and unstaged work, or the difference since a reference branch. You get a SARIF report and issue counts by severity.
run_security_scan
Analyzes the specific files or directories you point to, inside a given project path, and returns the same kind of report with findings sorted by severity.
What Claude asks before acting
By default, Claude pauses and asks for confirmation before each action it carries out on an account for someone, inside the conversation.
No source says whether Claude asks before starting a Black Duck scan, so that default rule is what applies. On Team and Enterprise workspaces, owners decide whether members may let some actions pass without a prompt every time, and they can restrict what a connector may do for the whole organization; nobody overrides that from their own account. Claude also works with the rights of the person who set it up and nothing more.
Which plans it runs on
No official source publishes plan availability connector by connector: 0 of the 819 directory sheets shows it, and the gap is real.
The published rule is general. Remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, while desktop extensions like this one install on Claude Desktop. On Team and Enterprise, an Owner or Primary Owner opens a connector for the organization before members connect. The connector's sheet in the official directory shows its current state. Only Black Duck documents this connector; no Claude help page covers it.
Where the Black Duck connector stops
A connector is not an automation. Claude calls these scans while it answers you, so nothing runs on its own when you commit or push.
By default, its sheet exposes only reading, an observed floor rather than a promise: an administrator can open actions that no public sheet shows. The partner badge is not a security audit, and Anthropic writes on every sheet that it neither chooses the tools a publisher exposes nor guarantees how they behave. Install what comes from a publisher you trust. To compare with a connector that works on a remote business account, see the Claude agility-cms connector.
Need help connecting Black Duck Security Scanner to Claude?
A person reads every message.